[Photo: Image generated by ChatGPT]

Financial authorities have expanded the scope of eased network separation rules for using artificial intelligence to include non-bank financial firms and electronic financial businesses, prompting expectations in the industry for broader use of AI and cloud services.

Large firms are reviewing whether to apply for the second test, while some in the non-bank sector say they have no plans to participate even if they meet eligibility requirements. Some also point to the risk that gaps could widen among financial firms in AI use and security responses if regulators further ease rules first for firms with AI and security capabilities.

◆ Lowering the bar for participation in the second test

On Sept. 3, the Financial Services Commission held the fifth meeting of the "Frontier AI Situation Response Task Force" with the Financial Supervisory Service and the Financial Security Institute and finalised detailed measures for the "second emergency easing steps" on network separation rules. The second test expands participation beyond large financial companies to include non-bank financial firms and electronic financial businesses.

Eligible applicants increase to 75 companies from 49 in the first test, and the number of selected participants expands to up to 15 from 10. The application threshold for financial companies is lowered to total assets of at least 2 trillion won and at least 300 full-time employees, from 10 trillion won and 1,000 employees. However, the chief information security officer (CISO) must not concurrently hold other information technology duties.

Separate criteria apply to electronic financial businesses. Annual electronic financial transaction volume must be at least 2 trillion won, and revenue related to electronic financial business must exceed 10 percent of total revenue. Their CISOs must also not concurrently hold other information technology duties. Under these criteria, the FSC says 59 financial companies and 16 electronic financial businesses qualify.

◆ Industry split between expectations and burden

Industry reaction is mixed. Large electronic financial firms are considering applications for the second test. An official at a large electronic financial firm said it is checking internally again whether it falls under the eligible applicants and is also reviewing whether to participate.

In the fintech industry, there is a positive assessment of the direction of easing network separation rules. That is because it broadens the scope for using fast-developing external technologies such as AI and cloud services in real work and services, and can reduce the cost and time needed to maintain the existing network separation system.

A fintech industry official said it is positive that the path to using external technologies such as AI and cloud services in real work and services is widening. The official added it is expected to cut the cost and time needed for network separation, while boosting digital competitiveness by increasing the speed of work automation, data use and new service development.

Still, expectations from the easing are not the same across all financial companies. Some in the non-bank sector say they do not plan to participate in the test for now even if they meet the eligibility requirements.

One interpretation is that it could be a burden for relatively smaller financial firms because even with eased rules they must prepare specialist AI and security personnel, related systems and alternative control measures on their own.

◆ Will gaps widen depending on AI capabilities?

The FSC will evaluate applicant companies not only by asset size and staffing levels but also by security capabilities and AI utilisation. Selected companies must also prepare alternative controls to network separation that can reduce the risk of data leaks and external intrusions if they want to use frontier AI and security software as a service.

Further easing of network separation rules is also likely to proceed centred on financial companies with such capabilities. The FSC is reviewing additional emergency easing steps and a plan to make the measures permanent based on the first and second test results and additional application demand. It is also discussing with related agencies a plan to fully lift network separation rules first for financial companies with advanced AI and security capabilities.

Behind the FSC's phased easing is the sophistication of cyber attacks using AI. In the first test, frontier AI showed an ability to analyse vast source code of millions to tens of millions of lines within hours and to broadly search for existing vulnerabilities. Authorities see a need to strengthen responses such as managing the attack surface, applying security patches quickly and building a system in which "AI defends against AI" if AI-enabled threats intensify.

But as security responses using AI become more important, a problem remains that the gap could widen between companies that can actually adopt such measures and those that cannot. That is because small and midsized financial firms and electronic financial businesses with limited investment capacity may be less likely to be selected for eased rules and also find it relatively difficult to build AI-based security response capabilities.

An official familiar with financial policy said if network separation rules are eased mainly for large firms with security and AI capabilities while small and midsized firms remain bound by regulations, smaller firms could have limited opportunities even to respond to AI attacks with AI. The official stressed there is also a need to prepare separate security measures for small and midsized financial firms and electronic financial businesses that are not included in the easing targets.

There are also concerns that the capacity for AI and security investment itself could lead to a competitiveness gap in the industry. The official said differences in companies' response capabilities could widen depending on how much personnel and budget they invest in AI security and how much authority their CISOs have. The official added that small and midsized firms could fall behind relatively.

Keyword

#Financial Services Commission #Financial Supervisory Service #Financial Security Institute #CISO #Frontier AI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.